New ISACA program assists with AWS audits


Monday, 06 May, 2019


New ISACA program assists with AWS audits

ISACA has launched a new audit program to support IT auditors in their assessments of Amazon Web Services (AWS) deployments.

The use of cloud services is widespread, and expected to only continue to increase — by 2020, it is estimated that 41% of enterprise workloads will be hosted on public cloud platforms.

While AWS has the ability to help teams become more agile, without proper knowledge of AWS configurations and potential hazards, enterprises may also open themselves to new risks.

ISACA’s new audit program, Amazon Web Services (AWS ) Audit Program, is designed to offer support with access to the AWS environment, as well as management and interrelationships of AWS services. The program covers AWS applications, functions and containers, and across the domains of governance, network configuration and management, asset configuration and management, logical access control, data encryption controls, logging and event management, security incident response and disaster recovery.

IT audit professionals can follow detailed testing steps outlined for controls across these domains in this audit program spreadsheet to assist in their auditing process, but they are encouraged to customise the document for their unique enterprise needs. The program is free to members, and $25 for non-members.

“ISACA’s AWS Audit Program provides IT audit professionals with the essentials for grasping the breadth and depth of AWS deployments as well as to provide them with a solid foundation for building their own customised audit program around these services,” said Adam Kohnke, CISA, CISSP, Senior IT Auditor for Total Administrative Services Corporation, and lead developer of the AWS Audit Program.

Kohnke elaborates on the topic in his ISACA Journal article, ‘Auditing Amazon Web Services’, published 1 May, which is available to members. In this feature, Kohnke covers the audit elements related to the eight domains covered in the audit program, while also providing a helpful overview of current AWS service offerings organised by category.

To download the Amazon Web Services (AWS) Audit Program, click here.

Image credit: ©stock.adobe.com/au/kentoh

Please follow us and share on Twitter and Facebook. You can also subscribe for FREE to our weekly newsletter and quarterly magazine.

Related News

AI to help workers return to the office

An AI tool developed by RMIT can prescribe the best physical working conditions for staff.

Digital offices likely to remain after COVID-19, survey shows

The pressure is on for businesses to rapidly establish a new model, with many employees resistant...

Govt issues tender for Regional Digital Tech Hub

The federal government says the hub will help regional Australians overcome the barriers they...


  • All content Copyright © 2020 Westwick-Farrow Pty Ltd